Home / Legal / Privacy Policy

Privacy Policy

Last updated: 10 October 2026

Note: This is an unofficial English translation provided for your convenience. The Turkish version is the legally binding text; in case of any discrepancy, the Turkish text prevails.

As LA Fish ("LA Fish"), we respect your privacy and treat the protection of your personal data as a priority responsibility. This policy explains how we collect, process, and protect data when you visit our website or use the LA Fish application.

This policy should be read together with the KVKK (Turkey's Personal Data Protection Law No. 6698) Information Notice. For the official disclosure under the KVKK, please review the KVKK Information Notice.

1. Information We Collect

1.1 When You Provide It to Us

  • Account information: First and last name and email address during registration.
  • Sign in with Apple / Sign in with Google: If you sign up or log in with one of these methods, the provider (Apple Inc. or Google LLC) sends us your name (with Apple, only on your first sign-in and only if you choose to share it), your email address (with Apple, a private relay address created by Apple if you choose to hide your email) and the user identifier the provider assigns to you. This information is used only to create your account and let you sign in; we never see your password with the provider. When you delete your account, this information is deleted as well, and the link with Apple is also removed on Apple's side.
  • Billing information: When purchasing a subscription — first and last name, billing address, tax ID number, or (only for individual e-invoicing) national ID number (TCKN), used as tax ID. Credit card information is processed directly by the payment institution; LA Fish does not see or store your full card number or CVC — only the token generated by the payment institution and the card's last 4 digits (for display purposes) are kept.
  • Contact forms: Information you share in your support or contact requests.
  • Service ratings (optional): When you rate a service you received: the provider's (company or technician) name, phone or email, city, your rating and your review.
  • Home and workplace address (optional): The home/workplace address you add in My Space; details other than country, province and district (neighbourhood, street, building and flat number, postcode) are stored encrypted. When you search for an address in My Space, the text you type is sent through our server to Google LLC's address service to find suggestions; your name, email and IP address are not sent. When you use Use My Location, your location is read once and converted to an address on your device; we do not store it and it is not sent to our servers.

1.2 What We Collect Automatically

  • Session data: Login IP address, session duration, device type, and operating system.
  • Usage statistics: Which features are used, the number of receipts processed (a numeric metric, not content).
  • Optional usage statistics (mobile app only, with your permission): Daily totals about which features are used, never linked to your account or device. See Section 1.3 below for details.
  • Error and crash logs: Error/crash logs and diagnostic information generated to ensure the stability and security of the application (via the error-tracking system on our own server). See Section 1.4 below for details.
  • Advertising data (Free tier only): Our advertising provider Google AdMob may collect your device's advertising identifier (on iOS only if you allow it), your IP address, device and app information, and your ad interactions. See section 5 below for details.
  • Cookies: Please review our Cookie Policy for details.

1.3 Optional Usage Statistics (Mobile App)

If you allow it, the mobile app sends events chosen from a fixed list about which features are used to our own server in Istanbul (e.g. "a receipt was added" and how it was added: manually or by scanning; "an item or document was added in My Space"; on first launch, whether the device language is Turkish, English or other). Only the platform (iOS or Android) is sent along with the events. Your name, email address, phone number, account, device or advertising ID, location, the time of the event, the app version, the device model and the contents of your records (receipt and document contents, merchants, amounts, spending categories) are not sent.

The server does not store individual events; it only increases daily totals. Your IP address is not written to these counts and is not recorded for this purpose. At the end of each day the counts are turned into aggregate tables and the raw counters are deleted; numbers smaller than five are never published in these tables, and the tables are kept for 24 months. The data is counted only on this server; it is not shared with third parties and is not used for advertising or sold. Like the app's other requests to our server, the request passes through our content delivery and security provider Cloudflare (see Section 5.2 of the KVKK Information Notice).

Permission is asked on first launch on the last step of the introduction with "Allow" and "Don't Allow" options; no answer is preselected and no usage data is sent until you choose. If you were already using the app, the same question is shown once after the update. You can change your choice at any time under Account > Data & Storage > Usage Analytics. While it is off, no usage data is sent; the moment you turn it off, sending stops and events not yet sent are deleted from the device. These statistics exist in version 1.1.2 and later of the mobile app; the website and the desktop app do not send usage statistics.

1.4 Error Reports

When the mobile app crashes or hits an error, the error type and its technical details, the app version, the device model and operating system information, and, when an error occurs on our server, the technical details of that error, are sent to the error-tracking system running on our own server in Istanbul. Reports contain no account information, email address or IP address; values such as session keys and passwords are masked before sending. Reports are used only to find and fix errors and are deleted after 60 days. The mobile app's reports also pass through Cloudflare.

Versions of the mobile app older than 1.1.2 may continue to send error reports to the error-tracking provider Sentry (Functional Software, Inc.; EU, Frankfurt region) for a while; these reports are kept there for 90 days. Once you update the app, reports go only to our own server.

2. How We Use Data

  • To create, verify, and manage your account,
  • To carry out subscription and payment transactions,
  • To provide technical support,
  • To ensure service security and integrity, and to find and fix errors using error reports,
  • If you give permission, to identify the most-used features and solve problems using aggregate usage statistics,
  • To fulfill legal obligations,
  • To send marketing messages if you give explicit consent,
  • To show ads and measure ad delivery on the Free tier,
  • To include subscription and product prices, without showing your identity or receipt details, in anonymous, aggregated price comparisons built from at least 3 different users (e.g. a cheaper plan from the same provider),
  • To use your service ratings, without showing your rating or review to anyone, only to recommend providers to other users by name and contact details,
  • When you ask, to research prices of your valuable items on stores' public product pages using brand and model (no personal data is sent to stores).

3. Receipt Images and Document Content

Receipt/invoice images that you upload to the LA Fish application or scan through the application may qualify as personal data. This data is processed as follows:

  • Local reading (all plans): Reading takes place entirely on the user's device; the image is not transmitted to the server for reading purposes. Unless you give explicit consent to the Cloud Receipt Archive described below, your image is not stored on LA Fish systems.
  • All plans – AI reading: The image is transmitted for processing to the Vertex AI infrastructure (Gemini model) of Google Cloud EMEA Limited (Ireland) over a secure TLS channel; processing takes place on servers in the EU (cross-border transfer). Inputs are not used for model training and are not stored permanently by Google. Once this temporary server-side processing is complete, the image is deleted from the server; unless you give consent to store the image in the Cloud Receipt Archive described below, your image is not retained by us.
  • Cloud Receipt Archive (optional, subject to your explicit consent): If you give explicit consent, the receipt fields that have been read (merchant name, date, time, receipt number, amount/tax base/VAT, payment type, category) are permanently stored on our server in Turkey; your tax ID or national ID number, if any, is kept encrypted, and, if you request it, the receipt image itself is also stored encrypted (storing the receipt image is subject to your plan's quota). Your receipts are kept separated according to the company/taxpayer you define. There is no cross-border transfer within this archive; the data is kept only on the server in Turkey (this is separate and independent from the consent for cross-border processing given for AI reading). Your data is retained until you withdraw your consent, delete the relevant receipt, or delete your account. You may withdraw your consent at any time; in that case, new receipts will not be archived. If you wish, you can turn on the "auto-delete oldest image" preference so that the oldest receipt image is deleted once your quota is full (in this case the receipt data is preserved and only the image is deleted). You can delete your receipts or images individually or in bulk from the "My Receipts" screen; if you delete your account, the receipt data, images, and company definitions in the archive are permanently deleted. When you request access to and portability of your data, the archived receipts and company definitions are also exported. Legal basis: your explicit consent under Article 5/1 of the KVKK.

Data within the receipt content (merchant name, amount, VAT) is recorded in the user database in structured form; this data is kept only in association with the user's account.

Card statements (Add From Card Statement, all plans): When you upload your bank's PDF statement or screenshots of the card transactions in your banking app in the mobile app, the statement, including the bank name, the card's last 4 digits and the transaction lines on it, is sent to the same processor as receipt reading, the Vertex AI infrastructure (Gemini model) of Google Cloud EMEA Limited (Ireland); processing takes place on servers in the EU (transfer abroad). The purpose is automatic reading of the transaction lines. Images and files are not used for model training and are not stored permanently by Google. The statement file is not stored in LA Fish systems; the lines that are read stay as an encrypted draft until you save them, and the draft is deleted once you save. The expenses you save are kept in your cloud receipt archive on our server in Türkiye under the archive rules above. Your full card number is never stored; only the last 4 digits are used. Reading statements requires you to accept the current version of the explicit consent text that covers card statements; consent you gave earlier remains valid for receipt reading.

4. Who We Share Your Data With

We do not sell or rent your personal data to third parties. Data is shared only in the following cases:

  • Service providers: Payment infrastructure, cloud storage (operating infrastructure), email service provider, advertising (Google AdMob, Free tier only), address suggestions (Google, only when you search for an address). These parties process data only on behalf of LA Fish and in accordance with its instructions.
  • Legal obligation: Sharing with authorized authorities as required by court order, administrative order, or legal regulations.
  • Business transfer: With the acquiring party in the course of a company merger or transfer; in this case, users are informed in advance.

Some of our service providers (e.g., email delivery, CDN/security, advertising, AI processing, address suggestions; error tracking in versions of the mobile app older than 1.1.2) are located abroad. For the complete list of cross-border transfers and their legal safeguards, please see Section 5.2 of the KVKK Information Notice.

5. Advertising

Ads are shown only on the Free tier, where the app occasionally shows full-screen ads. No ads are shown, and the advertising service is not started in the app at all, on paid plans (Standard, Premium and Premium Office), during the trial, or after the "Remove Ads" purchase. Ads are served through Google's advertising service AdMob.

  • Data collected: To show ads, measure whether an ad was viewed or tapped, and prevent fraudulent traffic, Google may collect your device's advertising identifier, your IP address, device information such as device model and operating system, app information, and your ad interactions.
  • Not shared: Your receipt and document contents, home/vehicle records, name, email address, and payment information are not shared with the advertising provider.
  • iOS: The advertising identifier (IDFA) is shared only if you grant the tracking permission the app asks for. If you don't, ads are shown without the advertising identifier. You can withdraw the permission at any time under Settings > Privacy & Security > Tracking.
  • Android: Outside the European Economic Area, the United Kingdom, and Switzerland, the app asks for your explicit permission to personalise ads; if you don't give it, ads are shown without personalisation. You can change your decision at any time under Account > Data & Storage > Ads. The advertising ID is provided by Google Play services. You can delete or reset it under Settings > Google > Ads (or Settings > Privacy > Ads, depending on your Android version); once deleted, it cannot be used for advertising.
  • European Economic Area, United Kingdom, and Switzerland: In these regions, Google's consent form is shown before any ad; ads are then personalised or served without personalisation according to your choice. You can change your choice under Account > Data & Storage > Ads > Ad Privacy Options.
  • How Google uses this data: policies.google.com/technologies/partner-sites

6. Security Measures

For the security of your data, we apply TLS 1.3 encrypted transmission; application-level AES-based (Fernet) encryption for sensitive fields (e.g., national ID number, accounting access credentials, and receipt images together with tax/national ID numbers in the cloud archive); access authorization controls; and regular security assessments. That said, we note that no transmission over the internet or electronic storage is 100% secure, and that we take reasonable precautions.

7. Children's Privacy

LA Fish services are not directed at individuals under the age of 18. We do not knowingly collect personal data belonging to individuals under 18. If you become aware that such data exists in our systems, please notify us at [email protected]; it will be deleted immediately.

8. Links to Other Sites

Our website may contain links to other websites. We are not responsible for the privacy practices of these sites; we recommend that you review their own privacy policies.

9. Changes to This Policy

This policy may be updated over time. You will be notified of significant changes by email and/or an in-app notification. The current text is always published on this page.

10. Contact

For questions about privacy, you may write to [email protected] with the subject line "Privacy".

11. Data Controller / Legal Information

CompanyYCT Sağlık Hizmetleri Ltd. Şti.
Registration (MERSİS)0946056894600001
Tax ID (VKN)9460568946
AddressAlacaatlı Mah. Park Cad. No: 15/15, Çankaya / Ankara
Email[email protected]
Phone+90 546 233 77 87